https://bugzilla.wikimedia.org/show_bug.cgi?id=50248

--- Comment #6 from Marc A. Pelletier <m...@uberbox.org> ---
Oh!  I figured out how they do it:  they have turned on log_input, log_output
or both in their sudo configuration -- this causes the creation of a pty (like
script does), and thus neatly circumvents the problem; the tty of the sudo-ed
user is brand new and owned by the user.

... at the cost of, you know, logging all the input and output of your session.

Needless to say, that will not happen in Tool Labs -- even having the
capability to replay users' sessions (including passwords typed and all!) would
be a *massive* violation of privacy.

I'm forced to wonder whether users of toolserver are aware that their sessions
are logged in this way.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
_______________________________________________
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to